Create a BlackBerry Dynamics Notification profile

  • Complete the default configuration for BlackBerry Work email notifications using the BlackBerry Mail (Push Notifications) service. For more information, see Steps to configure email notifications for BlackBerry Work in the BlackBerry Work, Notes, and Tasks Administration Guide. This default configuration is required to set up the BlackBerry Enterprise Mobility Server, and establishes the default email notification settings that BEMS will apply for any users that are not assigned a BlackBerry Dynamics Notification profile.
  • If you want to use the BEMS service account to authenticate with Microsoft Exchange Server (step 4 below), grant application impersonation permission to the service account.
  • In a Microsoft Exchange Online environment, if you want to use client-certificate authentication (step 4 below), obtain the client application ID with certificate-based authentication and create and associate a self-signed .pfx certificate to the Azure app ID for BEMS.
  • If your organization uses a hybrid environment, and you want to enable modern authentication (step 5 below), make sure that the on-premises Microsoft Exchange Server is configured to use hybrid modern authentication. For more information, see Microsoft 365: How to configure Exchange Server on-premises to use Hybrid Modern Authentication. If the Microsoft Exchange Server is not configured appropriately, users won't receive email notifications.
  • In an on-premises Microsoft Exchange Server environment, verify that the Microsoft Exchange Server is updated to support TLS 1.2, or push notifications will fail.
  1. In the management console, on the menu bar, click Policies and profiles > Policy > BlackBerry Dynamics Notification Profile.
  2. Click Add icon.
  3. Type a name and description for the profile.
  4. In the Authentication type section, select how you want BEMS to authenticate with Microsoft Exchange Server or Microsoft Exchange Online:

    Authentication option

    Steps

    Authenticate using a service account

    1. Select Credential.
    2. In the Service account username field, specify the username of the BEMS service account in the following format:
      • Microsoft Exchange Server: <domain>\<username> or UPN
      • Microsoft Exchange Online: <username>@<domain>
    3. In the Service account password field, specify the password of the service account.

    Authenticate using a client certificate

    1. Select Client certificate.
    2. Next to the Certificate file field, click the Browse button. Navigate to and select the .pfx client certificate.
    3. In the Password field, specify the certificate password.
  5. In a Microsoft Exchange Online environment, you must enable and configure modern authentication:
    1. Select Enable modern authentication.
    2. In the Authentication authority field, specify the URL of the authentication server that BEMS will access to retrieve the OAuth token for authentication with Microsoft Exchange Online (for example, https://login.microsoftonline.com/<tenantname> or https://login.microsoftonline.com/<tenantid>).
    3. In the Client app ID field, specify the client app ID.
    4. In the Server name field, specify the FQDN of the Microsoft Exchange Online server (for example, https://outlook.office365.com).
  6. If you want BEMS to obtain user information from Microsoft Exchange Server or Microsoft Exchange Online when it discovers users, in the Autodiscover URL override field, specify the autodiscover URL (for example, https://ad.example.com/autodiscover/autodiscover.svc).

    If you don't specify a URL, BEMS uses autodiscover to automatically locate the Microsoft Exchange Server or Microsoft Exchange Online.

  7. If you do not want BEMS to use HTTP redirection and DNS SRV lookups to retrieve the autodiscover URL, clear the Allow HTTP redirection and DNS SRV record check box.
  8. If you want BEMS to use the corporate network, through the BlackBerry Connectivity Node, to connect to Microsoft Exchange Server or Microsoft Exchange Online, rather than a direct connection from the BlackBerry Infrastructure, select the Use BlackBerry Connectivity Node route check box.
    This setting must be turned on if your environment uses Entra ID conditional access.
  9. In the Test account user email address field, specify an email address to use to test the connection from BEMS to Microsoft Exchange Server or Microsoft Exchange Online.
  10. If your environment uses Microsoft Exchange Online, select the Use Microsoft Graph client check box. If your environment still uses Microsoft Exchange Web Services (EWS), when you assign the profile, BEMS will automatically migrate Microsoft 365 users to Microsoft Graph at a rate of 60 users every 3 minutes. Do the following to allow BEMS to communicate with Microsoft Graph to access user mailboxes:
    1. Select how you want the BEMS service account to authenticate with Microsoft Graph:
      • Client secret: Obtain the client secret and paste it in the Client secret field.
      • Client certificate: Browse to and select the client certificate (.pfx) and specify the certificate password in the Password field.
    2. In the Authentication authority field, specify the URL of the authentication server that BEMS will access to retrieve the OAuth token for authentication with Microsoft Graph.
    3. In the Client app ID field, specify the client app ID.
    4. In the Server name field, specify the FQDN for Microsoft Graph.
    5. In the Test account user email address field, specify an email address to use to test the connection from BEMS to Microsoft Graph.
  11. For Active Directory users and groups that use the PSO (Password Settings Object) method to set the maximum password age, you can configure BlackBerry Work to display a warning message when a user's Active Directory password is about to expire. This feature requires the BlackBerry Connectivity Node. To enable this feature, do the following:
    1. Select the Enable password expiry check box.
    2. Specify the LDAP server name (for example, ldap.<DNS_domain_name>), LDAP port, LDAP logon account (domain\username or UPN for Microsoft Exchange Server or <username>@<domain> for Microsoft Exchange Online), and LDAP logon password.
    3. In the Base DN (Domain controller) field, specify the base DN for LDAP search.
    4. If you want to route data through an SSL-encrypted connection, select the Enable SSL LDAP check box. This requires you to import the LDAP certificate into the BEMS keystore. For instructions, see Create a trusted connection between BEMS Cloud and Microsoft Exchange Server.
    5. In the Test account user email address field, specify an email address to use to test the connection to the LDAP server.
  12. Click Save.
When you save the profile, the test accounts that you specified are used to verify connections to Microsoft Exchange Server or Microsoft Exchange Online, Microsoft Graph (if applicable), and the LDAP server (if applicable). If any of the connection tests do not succeed, an error message is displayed and the configuration is not saved. If this occurs, check your configuration and try again.
  • Assign the BlackBerry Cloud Enterprise Services (com.blackberry.gdservice-entitlement.cloud) entitlement to users to allow them to receive email notifications for BlackBerry Work. If the entitlement is not assigned, users will not receive email notifications.
  • Do one of the following to establish trust between BEMS and Microsoft Exchange Server or Microsoft Exchange Online:
  • If you created more than one BlackBerry Dynamics Notification profile, rank the profiles. The ranking will be used to determine which profile will be applied to a user when conflicts occur from group assignment. Only one BlackBerry Dynamics Notification profile can be applied to a user. The assignment of a BlackBerry Dynamics Notification profile will outrank the default configuration from Settings > BlackBerry Dynamics > Email notifications. If a user is not assigned a BlackBerry Dynamics Notification profile, the default configuration is applied.
  • Assign the profile to users and groups.